Malicious AI skills found on skills.sh after going dormant: why it is not safe to use
Researchers said malicious AI skills on skills.sh were updated after installation to steal secrets, and users must remove affected skills themselves.
What happened
TechRadar reported on August 7, 2026 that Zenity Labs found a credential-stealing campaign on skills.sh, a public registry for AI agent skills run by Vercel. A skill is a small add-on that gives an AI agent extra actions.
According to the report, attackers copied real skills and published lookalike names with small spelling changes. At first, the skills appeared harmless. Later, they were updated with instructions to send sensitive files and access tokens to attackers. A token is a secret code that lets software sign in to a service.
TechRadar said one malicious skill family reached 1.7 million aggregate installs. Zenity also found dozens of other malicious or risky skills, plus hundreds of empty or reserved names that may have been held for future attacks. The report says Vercel and Microsoft removed the identified skills after disclosure. People who already installed them still need to remove them manually.
What it means for you
If you use an AI agent, this is a reminder that add-ons can change over time. A skill that looks normal when installed may later be updated in a harmful way. For a normal user, the main risk is exposure of saved credentials or configuration files.
What to do instead
Review any skills you installed from public registries, especially ones with unusual names or recent updates. Remove anything you do not recognize or no longer use. Rotate exposed secrets such as SSH keys, cloud credentials, and service tokens if you think a skill had access to them. Keep sensitive files out of broad agent access where possible. Prefer trusted sources and smaller access permissions. AgentPod lists only reviewed, tested skills, which can help reduce risk, but you should still check what each skill can access before enabling it.
Sources:
- https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.